VulnerabilityModified
CVE-2018-12996
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
MEDIUM 6.1EPSS 3.46%
Does this matter?
Lower severity and a low EPSS score (3.46%). Track it; it rarely justifies an emergency change on its own.
Description
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 3.46% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zohocorp/manageengine applications manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/148635/Zoho-ManageEngine-13-13790-build-XSS-File-Read-File-Deletion.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Jul/71Exploit, Mailing List, Third Party Advisory
- http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201807-038Third Party Advisory
- https://github.com/unh3x/just4cve/issues/7Exploit, Third Party Advisory
- https://www.manageengine.com/products/applications_manager/issues.htmlVendor Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2018-12996.htmlVendor Advisory
- http://packetstormsecurity.com/files/148635/Zoho-ManageEngine-13-13790-build-XSS-File-Read-File-Deletion.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Jul/71Exploit, Mailing List, Third Party Advisory
- http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201807-038Third Party Advisory
- https://github.com/unh3x/just4cve/issues/7Exploit, Third Party Advisory
- https://www.manageengine.com/products/applications_manager/issues.htmlVendor Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2018-12996.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.